-
Notifications
You must be signed in to change notification settings - Fork 510
[Bugfix] Revert the removal of winlog.event_data fields #14756
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
Conversation
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
LGTM assuming the CI goes 🍏 .
Thanks.
|
Pinging @elastic/sec-windows-platform (Team:Security-Windows Platform) |
🚀 Benchmarks reportTo see the full report comment with |
💚 Build Succeeded
cc @w0rk3r |
|
|
Package system - 2.5.2 containing this change is available at https://epr.elastic.co/package/system/2.5.2/ |




Proposed commit message
Summary
Revert the removal of winlog.event_data fields. These are used in detection rules because they’re more reliable and more likely to be populated correctly across different versions of the Windows and System integrations, as well as Winlogbeat.
Checklist
changelog.ymlfile.